Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.542exploits catalogados
34.971CVEs com exploração pública
24.695testados em laboratório
13.947 exploits
GitHub PoC4
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49 (CVE-2021-41773)
CVE-2021-41773HIGHsob ataqueransomware06 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC38
CVE-2021-41773 Path Traversal vulnerability in Apache 2.4.49.
CVE-2021-41773HIGHsob ataqueransomware05 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC13
Exploitation of CVE-2021-41773 a Directory Traversal in Apache 2.4.49.
CVE-2021-41773HIGHsob ataqueransomware05 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC6
Poc.py
CVE-2021-41773HIGHsob ataqueransomware05 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC9
Path traversal in Apache HTTP Server 2.4.49 (CVE-2021-41773)
CVE-2021-41773HIGHsob ataqueransomware05 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC17
ZephrFish/CVE-2021-41773-PoC
CVE-2021-41773HIGHsob ataqueransomware05 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC39
lorddemon/CVE-2021-41773-PoC
CVE-2021-41773HIGHsob ataqueransomware05 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC52
iilegacyyii/PoC-CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware05 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC1
masahiro331/CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware05 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC8
CVE-2021-41773
CVE-2021-41773HIGHsob ataqueransomware05 out 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
Exploit para CVE-2019-15107 (Webmin 1.890-1.920) sin credenciales RCE escrito en PYTHON.
CVE-2019-15107CRITICALsob ataqueransomware05 out 2021
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISCO
abrir
GitHub PoC1
Working PowerShell POC
CVE-2021-1675HIGHsob ataqueransomware05 out 2021
Windows Print Spooler Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
The plugin does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly
CVE-2021-2456305 out 2021
Frontend Uploader <= 1.3.2 - Unauthenticated Stored Cross-Site Scripting
28RISCO
abrir
GitHub PoC25
Atlassian Jira Server/Data Center 8.4.0 - Arbitrary File read (CVE-2021-26086)
CVE-2021-26086MEDIUMsob ataque05 out 2021
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr
100RISCO
abrir
GitHub PoC13
Atlassian Confluence Server 7.5.1 Pre-Authorization Arbitrary File Read vulnerability (CVE-2021-26085)
CVE-2021-26085MEDIUMsob ataqueransomware05 out 2021
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authoriza
100RISCO
abrir
GitHub PoC
POC: CVE-2019-12840 (Authenticated RCE - Webmin Package Updates)
CVE-2019-1284005 out 2021
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISCO
abrir
GitHub PoC1
bypass all stages of the password reset flow
CVE-2021-27651CRITICAL05 out 2021
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to byp
75RISCO
abrir
GitHub PoC
Opensitoo/cve-2020-0796
CVE-2020-0796CRITICALsob ataqueransomware04 out 2021
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir
GitHub PoC9
H0j3n/CVE-2021-40444
CVE-2021-40444HIGHsob ataqueransomware03 out 2021
Microsoft MSHTML Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC7
Proof On Concept — Pulse Secure CVE-2021-22893
CVE-2021-22893CRITICALsob ataqueransomware03 out 2021
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windo
90RISCO
abrir
GitHub PoC2
Exploit code for CVE-2007-2447 written in Python3.
CVE-2007-244703 out 2021
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
GitHub PoC11
CVE-2021-21972 – ᴠᴍᴡᴀʀᴇ ᴄʟɪᴇɴᴛ ᴜɴᴀᴜᴛʜᴏʀɪᴢᴇᴅ ᴄᴏᴅᴇ ɪɴᴊᴇᴄᴛɪᴏɴ (ʀᴄᴇ)
CVE-2021-21972CRITICALsob ataqueransomware03 out 2021
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISCO
abrir
GitHub PoC2
CVE-2018-15961 — ᴀᴅᴏʙᴇ ᴄᴏʟᴅғᴜsɪᴏɴ (ʀᴄᴇ)
CVE-2018-15961CRITICALsob ataque03 out 2021
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISCO
abrir
GitHub PoC
wdjcy/CVE-2021-26084
CVE-2021-26084CRITICALsob ataqueransomware02 out 2021
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISCO
abrir
GitHub PoC22
the metasploit script(POC/EXP) about CVE-2021-22005 VMware vCenter Server contains an arbitrary file upload vulnerability
CVE-2021-22005CRITICALsob ataqueransomware02 out 2021
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISCO
abrir
GitHub PoC16
POC for scanning ProxyShell(CVE-2021-34523,CVE-2021-34473,CVE-2021-31207)
CVE-2021-34523CRITICALsob ataqueransomware02 out 2021
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISCO
abrir
GitHub PoC1
puckiestyle/CVE-2021-3493
CVE-2021-3493HIGHsob ataque02 out 2021
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISCO
abrir
GitHub PoC2
Exploit for CVE-2019-17662 (ThinVNC 1.0b1)
CVE-2019-1766202 out 2021
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RISCO
abrir
GitHub PoC1
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication is turned on during the deployment of the VNC server. The password for authentication is stored in cleartext in a file that can be read via a ../../ThinVnc.ini directory traversal attack vector.
CVE-2019-1766201 out 2021
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RISCO
abrir
GitHub PoC
CloudMe CVE-2018-6892 POC
CVE-2018-689201 out 2021
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RISCO
abrir
anteriorpágina 357 / 465próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.